Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-29133

Опубликовано: 20 мар. 2024
Источник: redhat
CVSS3: 4.4

Описание

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

A vulnerability was found in Apache Commons-Configuration2, where a Stack Overflow Error occurs when calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree. This issue could allow an attacker to trigger an out-of-bounds write that could lead to memory corruption or cause a denial of service condition.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientscommons-configuration2Not affected
A-MQ Clients 2commons-configuration2Fix deferred
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat build of Apache Camel 4 for Quarkus 3commons-configuration2Not affected
Red Hat build of Apache Camel for Spring Boot 3commons-configuration2Not affected
Red Hat build of Apache Camel for Spring Boot 4commons-configuration2Not affected
Red Hat build of OptaPlanner 8commons-configuration2Not affected
Red Hat Data Grid 8commons-configuration2Not affected
Red Hat Fuse 7commons-configuration2Out of support scope
Red Hat Integration Camel K 1commons-configuration2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2270673commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 2 года назад

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

CVSS3: 5.4
nvd
почти 2 года назад

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

CVSS3: 5.4
debian
почти 2 года назад

Out-of-bounds Write vulnerability in Apache Commons Configuration.This ...

CVSS3: 6.5
github
почти 2 года назад

Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree

CVSS3: 9.8
fstec
почти 2 года назад

Уязвимость функции ListDelimiterHandler.flatten(Object, int) библиотеки Apache Commons Configuration, позволяющая нарушителю выполнить произвольный код

4.4 Medium

CVSS3